NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
PyPI · #1817 most downloaded on PyPI
Minimal CLI coding agent by Mistral
Last release 11 days ago
23 Sep 2026
Ships on a steady schedule
a new release about every 9 days
Nearly every release is documented
notes for 60 of the last 60 stable releases
1 version withdrawn
withdrawn after publishing
10 months old
90 releases · first in 2025
One column per month.
Rust CLI: support for configuring Vibe Code remote projects
Copied inline notice, and only when autocopy is enabled.hideOther) is open now anchors from every box row instead of none./leanstall and /unleanstall now work on the unified backend instead of failing/leanstall and /unleanstall no longer crash the TUI on the unified backend~/.vibe/agents or .vibe/agents can be spawned againsystem_prompt_id runs on that prompt instead of the defaultrun_typescript program, instead of staying frozen until the program finishes.Allow /teleport with Vibe and workspace API keys, including free accounts, without an internal feature gate.
Vulnerability disclosure guidance and private reporting instructions in SECURITY.md.
--experimental-harness sessions can track todos, shown as a pinned line under the input and in full on /todo, and keep a per-session scratchpad whose notes are re-stated to the agent after the conversation is summarised./skills browser without removing it.vibe mcp add --allow-insecure-http and /mcp add --allow-insecure-http opt into plaintext http:// MCP servers on non-localhost hosts, such as a server on the LAN.r in the MCP servers & connectors panel to refresh the list on demand.--legacy-harness is the documented escape hatch back to the legacy Python harness.session_logging, project_context and experiments, rather than the whole group. Keys an admin does not set are taken from the user's own config instead of being reset to defaults.MistralAI-VibeCLI/<version> User-Agent header on MCP HTTP requests, letting the connectors gateway distinguish Vibe CLI tool calls from other MCP clients.session_logging.enabled = false is honoured again on the Unified Harness: the conversation and its attachments no longer land in the session save directory, the session log summary reports that logging is off, and --continue/--resume are refused with the same message the legacy backend gives.pre_tool and post_tool hooks now run for the skill tool, which previously took no hooks at all.&&, redirects, globs or $VAR now run through the shell.match now matches the tool the model actually calls, including edit and MCP tools./mcp login now recovers when a stored OAuth token refresh fails transiently (e.g. the server returns 5xx); it discards the stuck credentials and retries a fresh authorization instead of failing every retry.sort --files0-from now requires approval before reading listed files.ls 2>&1 or make >/dev/null, no longer ask for approval. Redirections that write to a file still do..vibe/ or .git/ configuration; it still asks before writing one.…could bypass workspace and denylist controls ( CVE-2026-87984 , CVE-2026-87985 , CVE-2026-87986 , CVE-2026-87987 , and residual CVE-2026-87988 variant…
@ file mentions now resolve against every workspace root, including --add-dir ones.@ mention outside the workspace no longer rejects the whole message; it stays plain text and the read tool can still ask for it.--add-dir no longer drops the working directory from the file tools' workspace roots.New /branch command forks the current conversation into a new resumable session, leaving the current session unchanged. Resume the copy in another ter
/branch command forks the current conversation into a new resumable session, leaving the current session unchanged. Resume the copy in another terminal with vibe --resume <id>.VS Code extension: debug submenu with log level picker, open log file, and a togglable session status panel showing agent statistics (steps, tokens, t
SessionBackendKind literals from "python"/"rust" to "legacy"/"unified" to match backend identity naming.~/.vibe now warns instead of passing silently: ConfigOrchestrator.set_field returns its errors rather than raising, so an ignored failure looked exactly like a successful write and the next session asked again with nothing to explain why.Desktop keeps 15 recent managed Code worktrees by default, configurable in Local Coding settings; cleanup skips active, dirty, untracked, or unpushed
/reload is in progressexperimental_enable_tab_status config option: shows >> (running) and ? (waiting) indicators in the terminal tab title.worktree plugin with a skill for creating, reusing, and cleaning up git worktrees under $VIBE_HOME/worktrees.env var MISTRAL_API_KEY, the keyring), so a shell-exported key shadowing the one saved at setup is visible.vibe and skill-creator skills now reach a session as skills of the shipped vibe plugin, so they are offered once, as /vibe:vibe and /vibe:skill-creator.session_logging.generate_titles = true to re-enable them.! command directly in the timeline: it is neither folded behind its own toggle nor gathered into the summary line that folds the agent's tool calls. Shell calls the model makes still fold, as every other tool result does./plugins detail view now leads with Author and Version, then the description, then Location (renamed from "Installed from"), Scope, Format, and Pinned./resume session picker now shows an animated loading indicator while saved sessions are discovered and waits briefly before loading a highlighted session preview, keeping rapid keyboard navigation responsive.git worktree add lands, so the session exists from the moment the prompt is sent instead of after the checkout. Only its first turn waits.DEBUG_MODE=true under vibe-acp/retry, which could only fail again with the same key./plugins with "Plugin namespace 'vibe' is reserved". Only a built-in may claim the reserved vibe namespace, but the re-resolve a session's plugin bind performs was re-reading every checkout at project scope, so the shipped vibe plugin was dropped from every session.! command that exits non-zero (or is interrupted) now shows what it printed. Only the exit status was reported before, which hid the stderr explaining it.~/.vibe/plugins/) were shown as project scope in /plugins because the bind-time resolve collapsed all staged checkouts to project scope. Scope is now preserved from the original discovery.git diff/show/blame, git log -p, git status -v); they defer to the classifier so a secret shown in a diff is not auto-readcd prefix (e.g. cd ~/.ssh && ls); the secret scan now reads the whole command, not the part after the cdui.ask_user_question; asking the user a clarifying question is the escalation channel itself, so it always runs instead of paying a classifier round-trip, being deny-and-continued, or escalating to an approval dialog to ask--smart-approve now keeps the mode in the Shift+Tab cycle for the whole session; it was selected at launch but dropped out of the cycle after switching to another mode, so you could not switch back to itprovided_tool_mode--check-upgrade and update, instead of an internal store-format validation error./skills browser for session skills, with search and filter; shared skills sync on session start. Experimental, off by default.
/skills browser for session skills, with search and filter; shared skills sync on session start. Experimental, off by default.browser_auth_allow_origin_rewrite rewrites sign-in/poll URLs onto configured origins/mcp, tagged with their plugin and authenticatable via /mcp login; a pending login is announced at session startask_user_question and exit_plan_modevibe update to check for and install a newer releaseagents/list no longer requires a session id/skills browser groups by scope, fits rows to width, and pages long listsvibe --yolo selects the auto-approve profile (cyclable with Shift+Tab; blockable via disabled_agents)[[mcp_servers]] entry is dropped with a warning instead of inheriting the configured credential/config saves to user config by default; Tab cycles user / session / (trusted) project target/mcp title marks an in-flight background refreshbrowser_auth_api_base_url port/whoami/mcp layout; rows render the first line only, [source] prefix stripped--yolo, --auto-approve, bypass_tool_permissions)vibe skill no longer recommends the removed /terminal-setup and now documents /copy, /paste-image, /remote-project/clear and /compact/config shows and edits the active model's effective auto-compaction threshold, preserving org-enforced global locksmove from a field relocation/mcp login no longer probes with a bare GET (405 before credentials); for a plugin server it sends the plugin's declared headers and uses its own URL, not a same-named [[mcp_servers]] entry from another session/mcp add under a plugin-owned name takes the name immediately for the configured entry/mcp refresh reconnects plugin servers, not just configured ones/mcp row with their own status and tools[[mcp_servers]] entry under a plugin-owned name no longer strands the plugin's server[[mcp_servers]] entries; each session's configured servers are its own/mcp no longer paints a failing-discovery source or unlinked connector as enabled before it comes upNoMatches/mcp opens from cache and waits 60s before refreshing; HTTP setup runs outside the UI loopdevstral-small-latest) from the default models list; stale sparse config overrides migrated automaticallyFuzzy search in the MCP servers and connectors browser
--worktree or --trust already grants accessSlash commands and setting pickers can be used while the agent or a command is running
Custom tools are flagged as deprecated
/log-level command for runtime log-level control/retry is exposed to ACP clients/ and supports ../ traversalInline ghost-text completion for mid-prompt skills
/clear and /new accept an optional first prompt and show the resume idask and defaults to accept-edits<cwd>/.vibeC:\c\... directories on Windows/clear resume hint gated on session persistabilityAdmin config layer for shared/enforced config that applies over user config
/model and /config to track the recommended model without pinning a specific alias_session/retrying notificationvibe.startup)autocopy_to_clipboard documenteddevstral-small thinking setting migrated to offmax_turn_requests stop reason instead of erroring on turn limit/resume listing speed no longer scales with total session count (persistent index)/retry command to retry an interrupted response
/retry command to retry an interrupted response/rewind now lets you choose between forking and rewinding in place/status shows provider prompt-cache usage and discounts cached tokens from the session costSkill-creator built-in skill: a guided flow to author, update, and delete your own skills
/config as a searchable, full-screen settings browser with typed edit modals and per-layer origin displayvibe-app-server binary for desktop integration.tar.gz archivesgrep result chips open the correct file and no longer leak absolute host paths into context (ACP)/rewind truncates in place instead of forkingCrash when @ -mentioning a file, which aborted the turn
@-mentioning a file, which aborted the turn[A/B testing] OS-native managed shell tools
vibe mcp add and vibe mcp remove commands to add and remove remote MCP servers without editing TOML-p, ACP) and the core engine, replacing direct AgentLoop/callback coupling with a typed, projected protocol/resume delete confirmationLC_CTYPE used instead of LC_ALL in the bash tool environmentOSError on over-long @-mention autocompletion candidates/mcp add/new command as an alias for /clear
/new command as an alias for /clearDefaultConfigLayer; config.toml stores only user-set valuesread_file no longer prompts for approval on plan files in plan modeRegistry skills content store and manifest for skill discovery
hooks.toml is now stable. Every hook type is renamed: post_agent_turn → post_agent, before_tool → pre_tool, after_tool → post_tool (the hook_event_name payload field is renamed to match). Update existing hooks.toml files accordingly.@file mentions now inject as read_file tool callsdecode_safeSKILL.md before parsing frontmatter/dev/tty is unavailable@file mention suggestions stretched to full widthcopy() for forkingenable_experimental_hooks config flag (and VIBE_ENABLE_EXPERIMENTAL_HOOKS env var); hooks now load unconditionally when declaredWarning when the Narrator is enabled without working audio output
Esc when the input is empty, with improved keybindingsask_user_question selection now works via mouse and supports free-text entry/exitExperimental managed bash tool for running and tracking shell sessions
--disabled-tools CLI flag to turn off specific tools for a run<tools-dir>/prompts/<name>.mdAGENTS.md files are now surfaced during read_file tool callsNO_PROXY--worktree NAME option to create or reuse a git worktree and run inside it
--worktree NAME option to create or reuse a git worktree and run inside itQuestionApp when submitting an empty multi-selectWhole-line content now shown in the edit diff
--continue now matches the resolved working directorymcp_servers names in config are now rejecteddefault_agent on new and resumed sessionsj/k navigation in selectable lists across the TUI (questions, theme picker, rewind, voice, MCP panels)
j/k navigation in selectable lists across the TUI (questions, theme picker, rewind, voice, MCP panels)ask_confirmation_on_exit config option to prompt before quitting.vibe/config.toml now persists config option changesask_user_question now supports more than 4 options and questions/mcp add slash command for adding OAuth MCP servers
/mcp add slash command for adding OAuth MCP serversClickable URLs in web fetch and web search tool output
/mcp panelCommands in /help are now listed alphabetically in both the CLI and ACP
/help are now listed alphabetically in both the CLI and ACP/teleport is now always available and shows an explicit error when its prerequisites aren't met, instead of being hidden/mcp login, /mcp logout, and /mcp status commands to authenticate OAuth-backed MCP servers from the TUI
/mcp login, /mcp logout, and /mcp status commands to authenticate OAuth-backed MCP servers from the TUIvibe --check-upgrade to force an immediate update check and exit--yolo as an alias for --auto-approveACP workspace trust gated behind the workspace-trust client capability
workspace-trust client capability/resume now opens much fasterFuzzy search in slash command autocomplete
/resume now scopes the session picker to the current foldermax_tokens instead of surfacing internal errors[Experimental] before_tool and after_tool hooks: shell scripts declared in hooks.toml that fire around every tool call; hooks can deny the call, rewri
before_tool and after_tool hooks: shell scripts declared in hooks.toml that fire around every tool call; hooks can deny the call, rewrite tool inputs, or append context to the output — enable with enable_experimental_hooks = true!bash command is running are queued and shown above the input; Esc pauses the queue, Ctrl+C drops the last queued message (LIFO), Enter flushes the queue when pausedls, cat, pwd, etc.) are allowed without approval by default[mcp_servers.auth] block in config for per-server MCP authenticationmax_turns support exposed over ACP via set_config_optionpost_agent_turn retries no longer use exit code 2; hooks must now exit 0 and return {"decision": "deny", "reason": "..."} on stdout to trigger a retry — exit code 2 is treated as a failure--resume now shows history when launched from a dangerous directoryweb_search are handled without crashing/teleport slash command exposed over ACP, mirroring the TUI command for IDE integrations
/teleport slash command exposed over ACP, mirroring the TUI command for IDE integrations/help instead of rejecting themsearch_replace name and now point to editImage attachments via @-mentions in the TUI for vision-capable models
@-mentions in the TUI for vision-capable modelssession/delete extension methodSKILL.md file fails to parse instead of silently dropping the skillEnvironmentLayer in the layered configuration, populated from VIBE_-prefixed environment variablesread and the file edit toolwrite_file is now create-only and refuses to overwrite existing filesagent-client-protocol to 0.10.1/mcp panel ordering now reflect which connectors are actually usable and the user's enable/disable choicesdisabled_tools from runtime is merged with the TOML configuration instead of replacing it, and is enforced inside ToolManager.get()shift+backspace and shift+delete now work in the chat inputtodo plan-update handler when the model's tool call failed validationenable_system_trust_store config flag to switch the shared SSL context to the OS trust store for corporate TLS / private CA setups
enable_system_trust_store config flag to switch the shared SSL context to the OS trust store for corporate TLS / private CA setupsSSL_CERT_FILE / SSL_CERT_DIR and the system trust store opt-inVS Code extension promo link in the CLI banner now points to the renamed mistralai.mistral-vibe-code extension
mistralai.mistral-vibe-code extensionCustom compaction prompts via the compaction_prompt_id config setting, resolved from ~/.vibe/prompts/ or .vibe/prompts/
compaction_prompt_id config setting, resolved from ~/.vibe/prompts/ or .vibe/prompts/--max-tokens flag for programmatic mode (-p)_auth/status and _auth/signOut extension methods so IDE extensions can show auth state and sign the user outvibe.setup.auth to classify the active credential sourceOverridesLayer and ProjectConfigLayer for the layered configuration system-p) no longer auto-approves tool calls by defaultenable_experimental_browser_sign_in flag is no longer required (stale entries are silently ignored)/teleport to Vibe Code Web now carries the working diff and last commit, matching the legacy teleport/teleport help and completion copy to say "Vibe Code Web"Load skills from ~/.agents/skills so they can be shared across agents
~/.agents/skills so they can be shared across agents/mcp with needs auth / needs setup labels and start the OAuth flow from inside the CLIminimal system prompt variant for eval and trainingsearch_replaceenabled/total in the bannerPretty session titles that format @mention syntax for human-readable display
@mention syntax for human-readable displaySessionInfoUpdate on the first prompt so IDE session pickers reflect the title immediatelyTomlFileLayer, ConfigBuilder, and ConfigOrchestratorD/E shortcuts in the detail view when there are no tools to enable or disablebash tool calls in ACP each render their own live terminal instead of racing on shared stateDeprecate retrying workflow status and expose retry source
--add-dir flag to pull additional repository roots into a session--no-autofill flag for bump_version.py script--continue scoping to current terminalenable_connectors config flag to control connector availabilitySyntax-highlighted file diffs for write_file and search_replace in the IDE agent webview
write_file and search_replace in the IDE agent webview! (bang) command outputprepare release script can resume after resolving merge conflicts/loop command to run a prompt or slash command on a recurring interval
/loop command to run a prompt or slash command on a recurring intervaldefault_agent config settingteleport command--helpenable_telemetry now takes precedence over enable_otelread_file flagged as truncated when the limit is reachedenable_telemetry takes precedence over enable_otel/rename command to rename the current session
/rename command to rename the current sessionfeat: vibe.at_mention_inserted telemetry eventvibe.ready telemetry fires soonerbash (!command) bang commands run via async subprocess for better latencymistral SDK to 2.4.4cryptography to address upstream CVEsnon_retryable flag on exceptions raised through _chat / _chat_streaming, so callers driving the agent loop from a Temporal activity can signal "do not retry"/clear no longer chains parent_session_id to the previous sessionvibe.new_session telemetry no longer fires when resuming a sessioncryptography)### Added ### Changed ### Fixed - Fix textual version ### Removed
Teleport surfaces the latest GitHub connection status while polling
Connector OAuth authentication flow in /mcp menu
/mcp menuConfigPatch operation types for Vibe Codeextra_headers field to ProviderConfigvibe.user_cancelled_action ACP telemetry coveragevibe.new_session telemetry event emitted whenever the session is resetmistral-medium-3.5Scratchpad directory for temporary working files shared with subagents
/copy slash command--trust session-only flag and fail-fast behavior in -p modeConfigLayer for layered configuration resolution~/.vibe/prompts overrides for builtin prompts/mcp menu/compactvibe.ready telemetry eventauto_approve config to bypass_tool_permissions--continue now only looks for sessions of the current working directoryMallocStackLogging error messages suppressed in CLI inputindex.lock leftover on interrupted deferred initfind commands allowed by default### Fixed - Fixed changelog and whats_new
Builtin skills system with self-awareness skill
cwd configuration parameter for MCP stdio servers/connectors as alias for /mcp and R refresh shortcut in MCP browserMergeFieldMetadata and annotated merge strategy helpers for config schemasvibe.request_sent telemetry event fired before each LLM API calltool_call_finished telemetry eventrequest_sent telemetry fields and added nb_prompt_chars/mcp menu by connection state then alphabetically/debug command no longer throws/terminal-setup commandMergeStrategy enum and merge logic for configuration
MergeStrategy enum and merge logic for configurationcall_source=vibe_code field in LLM request metadataapi.mistral.aiapi_base parsingDisplay detected files and LLM risks in trust folder dialog
read_safe for non-UTF-8 filesConsole View for enhanced debugging and monitoring
/mcp command to display MCP servers and their status/data-retention slash command to view Mistral AI's data retention notice and privacy settings
/data-retention slash command to view Mistral AI's data retention notice and privacy settingsAlt+Left / Alt+Right keyboard shortcuts for word-wise cursor movement in chat input
ACP message-id support for reliable message boundary identification
Rewind mode to navigate and fork conversation history
Pinned agent-client-protocol dependency back to 0.8.1
Loosened agent-client-protocol version constraint from pinned to minimum bound
OTEL tracing support for observability
exit_plan_mode tool only in plan modeDedicated theorem proving agent powered by leanstral, setup with /leanstall
find from bash default allowlist to prevent -exec abuseSession ID included in telemetry events for better tracing
file_content_before from Vibe Code, reducing payload sizeYour coding agent can read these notes before it upgrades. Set up the MCP server →